FreshRSS

πŸ”’
☐ β˜† βœ‡ Threatpost | The first stop for security news

Ransomware Attacks are on the Rise

By Nate Nelson β€” August 26th 2022 at 16:44
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Cybercriminals Are Selling Access to Chinese Surveillance Cameras

By Nate Nelson β€” August 25th 2022 at 18:47
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Firewall Bug Under Active Attack Triggers CISA Warning

By Threatpost β€” August 23rd 2022 at 13:19
CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.
☐ β˜† βœ‡ Threatpost | The first stop for security news

iPhone Users Urged to Update to Patch 2 Zero-Days

By Elizabeth Montalbano β€” August 19th 2022 at 15:25
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Google Patches Chrome’s Fifth Zero-Day of the Year

By Elizabeth Montalbano β€” August 18th 2022 at 14:31
An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Xiaomi Phone Bug Allowed Payment Forgery

By Nate Nelson β€” August 16th 2022 at 12:26
Mobile transactions could’ve been disabled, created and signed by attackers.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Black Hat and DEF CON Roundup

By Threatpost β€” August 15th 2022 at 13:56
β€˜Summer Camp’ for hackers features a compromised satellite, a homecoming for hackers and cyberwarfare warnings.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Feds: Zeppelin Ransomware Resurfaces with New Compromise, Encryption Tactics

By Elizabeth Montalbano β€” August 12th 2022 at 18:20
The CISA has seen a resurgence of the malware targeting a range of verticals and critical infrastructure organizations by exploiting RDP, firewall vulnerabilities.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Microsoft Patches β€˜Dogwalk’ Zero-Day and 17 Critical Flaws

By Threatpost β€” August 10th 2022 at 12:48
August Patch Tuesday tackles 121 CVEs, 17 critical bugs and one zero-day bug exploited in the wild.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Open Redirect Flaw Snags Amex, Snapchat User Data

By Elizabeth Montalbano β€” August 5th 2022 at 13:17
Separate phishing campaigns targeting thousands of victims impersonate FedEx and Microsoft, among others, to trick victims.
☐ β˜† βœ‡ Threatpost | The first stop for security news

VMWare Urges Users to Patch Critical Authentication Bypass Bug

By Elizabeth Montalbano β€” August 3rd 2022 at 15:23
Vulnerabilityβ€”for which a proof-of-concept is forthcomingβ€”is one of a string of flaws the company fixed that could lead to an attack chain.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Universities Put Email Users at Cyber Risk

By Elizabeth Montalbano β€” August 2nd 2022 at 23:02
DMARC analysis by Proofpoint shows that institutions in the U.S. have among some of the poorest protections to prevent domain spoofing and lack protections to block fraudulent emails.
☐ β˜† βœ‡ Threatpost | The first stop for security news

Malicious Npm Packages Tapped Again to Target Discord Users

By Elizabeth Montalbano β€” July 29th 2022 at 15:07
Recent LofyLife campaign steals tokens and infects client files to monitor various user actions, such as log-ins, password changes and payment methods.
☐ β˜† βœ‡ Threatpost | The first stop for security news

IoT Botnets Fuels DDoS Attacks – Are You Prepared?

By Sponsored Content β€” July 26th 2022 at 12:38
The increased proliferation of IoT devices paved the way for the rise of IoT botnets that amplifies DDoS attacks today. This is a dangerous warning that the possibility of a sophisticated DDoS attack and a prolonged service outage will prevent businesses from growing.
☐ β˜† βœ‡ Threatpost | The first stop for security news

CISA Urges Patch of Exploited Windows 11 Bug by Aug. 2

By Threatpost β€” July 18th 2022 at 12:19
Feds urge U.S. agencies to patch a Microsoft July Patch Tuesday 2022 bug that is being exploited in the wild by August 2.
❌